From 9cdabec0b8baae3671208f9caab614bc913a42eb Mon Sep 17 00:00:00 2001 From: JosanaDH <113072344+JosanaDH@users.noreply.github.com> Date: Thu, 21 Sep 2023 09:42:06 +1000 Subject: [PATCH 1/2] Update package.json to incl postcss-values-parser to bring a lic vuln --- package.json | 1 + 1 file changed, 1 insertion(+) diff --git a/package.json b/package.json index 3f95108c42..86e36eef48 100644 --- a/package.json +++ b/package.json @@ -15,6 +15,7 @@ "test": "snyk test" }, "dependencies": { + "postcss-values-parser": "6.0.2", "adm-zip": "0.5.2", "body-parser": "1.9.0", "cfenv": "^1.0.4", From b92549adfc907d6d695a877c69a1df19305c08b6 Mon Sep 17 00:00:00 2001 From: JosanaDH <113072344+JosanaDH@users.noreply.github.com> Date: Thu, 21 Sep 2023 09:44:30 +1000 Subject: [PATCH 2/2] Update .snyk --- .snyk | 7 +------ 1 file changed, 1 insertion(+), 6 deletions(-) diff --git a/.snyk b/.snyk index 1dacb3e279..caad60d435 100644 --- a/.snyk +++ b/.snyk @@ -1,11 +1,6 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. version: v1.25.0 -ignore: - 'snyk:lic:npm:postcss-values-parser:MPL-2.0': - - '*': - reason: Given the library is employed during the build step which is non-distributed, it is compliant. - expires: 2033-09-15T05:46:34.098Z - created: 2023-09-15T05:46:34.102Z +ignore:{} patch: {} exclude: global: